# admin user for a single Project only ?

**URL:** <https://forums.suse.com/t/admin-user-for-a-single-project-only/26430>\
**Category:** SUSE OpenStack Cloud\
**Created:** [November 29, 2014, 11:28pm UTC](https://forums.suse.com/t/admin-user-for-a-single-project-only/26430 "2014-11-29T23:28:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharfuddin](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sharfuddin](https://forums.suse.com/u/sharfuddin)\
**Post date:** [November 29, 2014, 11:28pm UTC](https://forums.suse.com/t/admin-user-for-a-single-project-only/26430/1 "2014-11-29T23:28:04Z")

</div>

per the admin guide[quote]  
The admin role is global. If you assign a user to a project and give him the  
admin role, the user can also add himself as an administrator for other  
projects and thus gain full administrative rights across all projects.  
[/quote]

how can I create admin user for a specific/single Project(OU) only ?

---

<div class="post-metadata">

**Author:** ![a\_jaeger](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@a\_jaeger](https://forums.suse.com/u/a_jaeger)\
**Post date:** [December 1, 2014, 9:46am UTC](https://forums.suse.com/t/admin-user-for-a-single-project-only/26430/2 "2014-12-01T09:46:23Z")

</div>

[QUOTE=sharfuddin;25156]per the admin guide

how can I create admin user for a specific/single Project(OU) only ?[/QUOTE]

What kind of rights should your admin user have on that project?

---

<div class="post-metadata">

**Author:** ![sharfuddin](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sharfuddin](https://forums.suse.com/u/sharfuddin)\
**Post date:** [December 1, 2014, 9:46pm UTC](https://forums.suse.com/t/admin-user-for-a-single-project-only/26430/3 "2014-12-01T21:46:52Z")

</div>

> [@a\_jaeger;25163](#):
>
> What kind of rights should your admin user have on that project?

1. that admin can create and delete users for his project(organization) only
2. that admin can create/delete resources(e.g Images) and make them available/unavailable to users of his project(organization) only

I mean any possible administrative activity but on his own project only, rather a global admin.

---

<div class="post-metadata">

**Author:** ![a\_jaeger](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@a\_jaeger](https://forums.suse.com/u/a_jaeger)\
**Post date:** [December 2, 2014, 10:04am UTC](https://forums.suse.com/t/admin-user-for-a-single-project-only/26430/4 "2014-12-02T10:04:54Z")

</div>

The policy.json files configure access control, for the images, see [http://docs.openstack.org/juno/config-reference/content/section\_glance-policy.json.html](http://docs.openstack.org/juno/config-reference/content/section_glance-policy.json.html). But I’m not aware how this can be limited to specific projects only.
